CVE-2015-0812

Publication date 1 April 2015

Last updated 24 July 2024


Ubuntu priority

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

Status

Package Ubuntu Release Status
firefox 14.10 utopic
Fixed 37.0+build2-0ubuntu0.14.10.1
14.04 LTS trusty
Fixed 37.0+build2-0ubuntu0.14.04.1
12.04 LTS precise
Fixed 37.0+build2-0ubuntu0.12.04.1
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

Other references